CVE-2019-12278
NixOS vulnerability analysis and mitigation

Overview

Opera for Android browser was found to be vulnerable to an address bar spoofing vulnerability (CVE-2019-12278). The issue affects Opera Browser version 52.1.2517.139570 and earlier versions, impacting over 2.8 million devices. The vulnerability was discovered in May 2019 and involves the mishandling of certain Unicode characters from languages such as Persian and Arabic that are displayed in right-to-left order (Opera Spoofing).

Technical details

The vulnerability exploits the Unicode Bidirectional Algorithm where specific Unicode characters (such as U+08FF, U+FB50) are rendered from right to left. This behavior allows attackers to manipulate URL display in the address bar. The browser fails to properly handle these special characters and instead of showing URLs in Punycode format, it renders them in a way that could deceive users (Opera Spoofing).

Impact

The vulnerability poses a significant security risk as it allows attackers to spoof legitimate website URLs in the address bar, potentially deceiving users into believing they are visiting trusted websites. This is particularly concerning as the URL bar is often the primary security indicator for non-technical users, and the spoofing can occur even with HTTPS padlock indicators present (Opera Spoofing).

Mitigation and workarounds

The vulnerability was reported on May 21, 2019, and was fully fixed by July 29, 2019. The solution involves ensuring all URLs are rendered consistently from left to right and implementing proper handling of Unicode characters in accordance with RFC standards (Opera Spoofing).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management